Observed gap
The exact gateway images in security run35784440806 install Wolfi libexpat1 2.8.5-r0 on amd64 and arm64. Neither retained Trivy report lists a libexpat1 vulnerability. Upstream issue1076 describes CVE-2025-66382 as a denial-of-service issue affecting all releases; issue1160 tracks additional unresolved or unvalidated reports.
The 2.8.5 changelog fixes CVE-2026-93990 but retains the broader warning. The 2.8.4 changelog already carries that warning. This is a pre-existing dependency/advisory-coverage question surfaced during PR#87, not an established regression in shared evidence admission.
Acceptance
- Identify exact native and Python callers of the installed gateway Expat library and whether untrusted input can reach affected parsing paths.
- Reconcile the upstream CVE and unresolved-report status with the scanner's advisory coverage and exact package provenance. Distinguish validated public issues from reports without enough public detail.
- Apply a supported fix when available. If mitigation or non-applicability is proposed, follow the existing exact-image evidence and independent-maintainer disposition process.
- Preserve raw scanner results and document residual uncertainty. An active maintenance entry or absent scan finding does not establish that a vulnerable parser is unreachable.
No vulnerability suppression or gateway reachability verdict is authorized by this issue. The proposed PR#87 maintenance entry records active distribution maintenance only. Exact APK/index metadata and source hashes are retained in the originating task's concurrency-maintenance evidence.
Observed gap
The exact gateway images in security run35784440806 install Wolfi libexpat1 2.8.5-r0 on amd64 and arm64. Neither retained Trivy report lists a libexpat1 vulnerability. Upstream issue1076 describes CVE-2025-66382 as a denial-of-service issue affecting all releases; issue1160 tracks additional unresolved or unvalidated reports.
The 2.8.5 changelog fixes CVE-2026-93990 but retains the broader warning. The 2.8.4 changelog already carries that warning. This is a pre-existing dependency/advisory-coverage question surfaced during PR#87, not an established regression in shared evidence admission.
Acceptance
No vulnerability suppression or gateway reachability verdict is authorized by this issue. The proposed PR#87 maintenance entry records active distribution maintenance only. Exact APK/index metadata and source hashes are retained in the originating task's concurrency-maintenance evidence.